20cf4b7849
Fix various permission & login related bugs ( #36002 ) ( #36004 )
...
Backport #36002
Permission & protection check:
- Fix Delete Release permission check
- Fix Update Pull Request with rebase branch protection check
- Fix Issue Dependency permission check
- Fix Delete Comment History ID check
Information leaking:
- Show unified message for non-existing user and invalid password
- Fix #35984
- Don't expose release draft to non-writer users.
- Make API returns signature's email address instead of the user
profile's.
Auth & Login:
- Avoid GCM OAuth2 attempt when OAuth2 is disabled
- Fix #35510
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-11-22 12:33:48 +00:00
d67cd622d0
Fix corrupted external render content ( #35946 ) ( #35950 )
...
Backport #35946 by wxiaoguang
Fix #35944
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-11-14 02:15:36 +00:00
15f3e9d5a5
Don't show unnecessary error message to end users for DeleteBranchAfterMerge ( #35937 ) ( #35941 )
...
Backport #35937 by wxiaoguang
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-11-12 23:31:05 +00:00
01fa8b2b7e
Limit read bytes instead of ReadAll ( #35928 ) ( #35934 )
...
Backport #35928 by wxiaoguang
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-11-13 02:26:27 +08:00
01873a99c1
Allow to display embed images/pdfs when SERVE_DIRECT was enabled on MinIO storage ( #35882 ) ( #35917 )
...
Backport #35882 by lifegpc
Co-authored-by: lifegpc <g1710431395@gmail.com >
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-11-11 02:24:06 +00:00
1ca4fef611
Fix team member access check ( #35899 ) ( #35905 )
...
Backport #35899 by wxiaoguang
Fix #35499
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-11-09 03:44:53 +00:00
8116742e2d
Fix viewed files number is not right if not all files loaded ( #35821 ) ( #35844 )
...
Fix #35803
Backport #35821
Signed-off-by: silverwind <me@silverwind.io >
Co-authored-by: silverwind <me@silverwind.io >
2025-11-03 17:19:50 -08:00
04b6f90889
Fix actions rerun bug ( #35783 ) ( #35784 )
...
Backport #35783
Fix #35780 , fix #35782
Rerunning a job or a run is only allowed when the job is done and the
run is done.
Related PR: #34970
https://github.com/go-gitea/gitea/blob/98ff7d077376db1225f266095788c6bd9414288a/routers/web/repo/actions/view.go#L239
We don't need to check run status again in `rerunJob` because the run
status has been changed before `rerunJob`.
---
In fact, the bug described in the above issues will not occur on the
main branch. Because `getRunJobs` is called before updating the run.
https://github.com/go-gitea/gitea/blob/98ff7d077376db1225f266095788c6bd9414288a/routers/web/repo/actions/view.go#L425-L435
So the run status that `rerunJob` checks is the old status.
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-10-30 09:31:42 +01:00
Giteabot and GitHub
88a8571b93
Update tab title when navigating file tree ( #35757 ) ( #35772 )
...
Backport #35757 by bytedream
2025-10-29 14:04:19 +00:00
wxiaoguang and GitHub
b2f2f8528a
Fix external render, make iframe render work ( #35727 , #35730 ) ( #35731 )
...
Backport #35727 and #35730
---------
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com >
2025-10-23 16:07:17 +08:00
0925089b5e
Honor delete branch on merge repo setting when using merge API ( #35488 ) ( #35726 )
...
Backport #35488 by @kemzeb
Fix #35463 .
---------
Co-authored-by: Kemal Zebari <60799661+kemzeb@users.noreply.github.com >
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-10-22 09:41:40 -07:00
cb338a2ba1
fix attachment file size limit in server backend ( #35519 ) ( #35720 )
...
Backport #35519 by @a1012112796
fix #35512
Co-authored-by: a1012112796 <1012112796@qq.com >
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-10-21 18:01:59 +00:00
ChristopherHX and GitHub
46f695ac65
Fix workflow run event status while rerunning a failed job ( #35689 ) ( #35703 )
...
The event reported a completion status instead of requested, therefore
sent an email
Backport #35689
2025-10-19 10:49:20 -07:00
Giteabot and GitHub
4af1d58c86
Fix various bugs ( #35684 ) ( #35696 )
...
Backport #35684 by wxiaoguang
2025-10-19 02:26:03 +08:00
f71df88a6b
Use LFS object size instead of blob size when viewing a LFS file ( #35679 ) ( #35680 )
...
Backport #35679 by surya-purohit
shows the main LFS filesize instead of the pointer filesize when viewing
a file
Co-authored-by: Surya Purohit <suryaprakash.sharma@sourcefuse.com >
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-10-16 22:41:24 +08:00
f4512426a1
Fix code tag style problem and LFS view bug ( #35628 ) ( #35636 )
...
Backport #35628 by lutinglt
Signed-off-by: 鲁汀 <131967983+lutinglt@users.noreply.github.com >
Co-authored-by: 鲁汀 <131967983+lutinglt@users.noreply.github.com >
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-10-11 20:25:03 +00:00
006fe2a907
Add rebase push display wrong comments bug ( #35560 ) ( #35580 )
...
Backport #35560 by @lunny
Fix #35518
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com >
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-10-04 10:28:32 +02:00
6c8879b832
Fix markup init after issue comment editing ( #35536 ) ( #35537 )
...
Backport #35536 by wxiaoguang
Fix #35533
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-09-26 07:11:21 +08:00
Lunny Xiao and GitHub
198f37e33c
Move updateref and removeref to gitrepo and remove unnecessary open repository ( #35511 )
...
Extracted from #35077
`UpdateRef` and `RemoveRef` will call git commands even for gogit
version.
2025-09-19 08:04:18 -07:00
9a0ec53ee3
Stream repo zip/tar.gz/bundle achives by default ( #35487 )
...
Initial implementation of linked proposal.
* Closes #29942
* Fix #34003
* Fix #30443
---------
Co-authored-by: silverwind <me@silverwind.io >
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-09-19 11:51:21 +08:00
Lunny Xiao and GitHub
9332ff291b
Move git command to git/gitcmd ( #35483 )
...
The name cmd is already used in many places and may cause conflicts, so
I chose `gitcmd` instead to minimize potential naming conflicts.
2025-09-15 23:33:12 -07:00
wxiaoguang and GitHub
4fe1066a17
Replace gobwas/glob package ( #35478 )
...
https://github.com/gobwas/glob is unmaintained and has bugs.
2025-09-13 18:01:00 +00:00
84812e42df
Fix SSH signing key path will be displayed in the pull request UI ( #35381 )
...
Closes #35361
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-09-12 03:00:18 +00:00
Lunny Xiao and GitHub
274f4aea7e
Fix a compare page 404 bug when the pull request disabled ( #35441 )
2025-09-09 21:04:32 -07:00
d2e994db2c
Move git config/remote to gitrepo package and add global lock to resolve possible conflict when updating repository git config file ( #35151 )
...
Partially fix #32018
`git config` and `git remote` write operations create a temporary file
named `config.lock`. Since these operations are not atomic, they must
not be run in parallel. If two requests attempt to modify the same
repository concurrently—such as during a compare operation—one may fail
due to the presence of an existing `config.lock` file.
In cases where `config.lock` is left behind due to an unexpected program
exit, a global lock mechanism could allow us to safely remove the stale
lock file when a related error is detected. While this behavior is not
yet implemented in this PR, it is planned for a future enhancement.
---------
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com >
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-09-01 18:47:04 +00:00
Lunny Xiao and GitHub
4e1b8db1fc
Move HasWiki to repository service package ( #33912 )
...
Move HasWiki out of the models package to avoid referencing the absolute
wiki path directly.
2025-09-01 11:12:58 -07:00
aef4a3514c
Remove the duplicated function GetTags ( #35375 )
...
This PR removes the GetTags function from the git module and keeps only
GetTagInfos. All previous usages of GetTags have been replaced with
database-based tag functions.
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-08-29 01:11:42 +00:00
wxiaoguang and GitHub
0cbaa0b662
Remove incorrect "db.DefaultContext" usages ( #35366 )
2025-08-28 03:52:43 +00:00
wxiaoguang and GitHub
60246730b5
Remove wrong "git.DefaultContext" ( #35364 )
2025-08-27 16:31:21 +00:00
c7b99c8cc7
Prevent duplicate actions email ( #35215 )
...
Trying to prevent duplicate action emails by adding an extra check on job status.
---------
Signed-off-by: NorthRealm <155140859+NorthRealm@users.noreply.github.com >
Co-authored-by: Christopher Homberger <christopher.homberger@web.de >
2025-08-24 09:30:56 -07:00
Nicolas Auvray and GitHub
c760e3b2b5
Display pull request in merged commit view ( #35202 )
...
Fixes #34634
---
I am not a Web dev so I'm open to any change on the design. The
important thing for me is to have the feature implemented.
Here are screenshots on a test instance:
<img width="2758" height="420" alt="Capture d'écran 2025-08-02 161710"
src="https://github.com/user-attachments/assets/30abbeb5-6139-4a91-9348-36e78f1646e6 "
/>
<img width="2769" height="520" alt="Capture d'écran 2025-08-02 161725"
src="https://github.com/user-attachments/assets/29871f05-f0b5-4a31-9ada-812780269c7d "
/>
2025-08-04 23:30:12 +00:00
Lunny Xiao and GitHub
be2a6b4414
Fix bug when review pull request commits ( #35192 )
...
The commit range in the UI follows a half-open, half-closed convention:
(,]. When reviewing a range of commits, the beforeCommitID should be set
to the commit immediately preceding the first selected commit. For
single-commit reviews, we must identify and use the previous commit of
that specific commit.
The endpoint ViewPullFilesStartingFromCommit is currently unused and can
be safely removed.
Fix #35157
Replace #35184
Partially extract from #35077
2025-08-03 10:23:10 -07:00
Lunny Xiao and GitHub
84d31bc842
A small refactor to use context in the service layer ( #35179 )
2025-07-31 03:43:54 +00:00
wxiaoguang and GitHub
c3f5ea3b1f
Fix repo file list partial reloading for submodules ( #35183 )
...
Fix the TODO and add more tests
2025-07-31 09:34:51 +08:00
wxiaoguang and GitHub
8f91bfe9d8
Fix submodule parsing when the gitmodules is missing ( #35109 )
...
Follow up #35096 , fix #35095 , fix #35115 and add more tests
The old code used some fragile behaviors which depend on the "nil"
receiver. This PR should be a complete fix for more edge cases.
2025-07-18 09:42:44 +00:00
Lunny Xiao and GitHub
37958e486a
Rename pull request GetGitRefName to GetGitHeadRefName ( #35093 )
2025-07-16 21:33:33 +08:00
e1e4815a1c
Redirect to a presigned URL of HEAD for HEAD requests ( #35088 )
...
Resolves https://github.com/go-gitea/gitea/issues/35086 .
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-07-16 11:22:45 +00:00
d08459820d
Improve submodule relative path handling ( #35056 )
...
Fix #35054
---------
Co-authored-by: Giteabot <teabot@gitea.io >
2025-07-14 23:28:34 +08:00
32152a0ac0
Also display "recently pushed branch" alert on PR view ( #35001 )
...
This commit adds the "You recently pushed to branch X" alert also to PR
overview, as opposed to only the repository's home page.
GitHub also shows this alert on the PR list, as well as the home page.
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
Co-authored-by: Giteabot <teabot@gitea.io >
2025-07-10 17:17:56 +00:00
NorthRealm and GitHub
6b42ea1e54
Rerun job only when run is done ( #34970 )
...
For consistency, limit rerunning Job(s) to only when Run is in Done status.
2025-07-06 10:47:02 -07:00
silverwind and GitHub
95a935aca0
Enable gocritic equalFold and fix issues ( #34952 )
...
Continuation of https://github.com/go-gitea/gitea/pull/34678 .
---------
Signed-off-by: silverwind <me@silverwind.io >
2025-07-06 16:53:34 +00:00
wxiaoguang and GitHub
e0745eb14d
Refactor webhook and fix feishu/lark secret ( #34961 )
2025-07-06 06:04:08 +00:00
wxiaoguang and GitHub
70685a9489
Fix git graph page ( #34948 )
...
fix #34946
2025-07-04 15:41:19 +00:00
wxiaoguang and GitHub
90f96c301e
Fix PR toggle WIP ( #34920 )
...
Fix #34919
---------
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com >
2025-07-01 16:32:39 +08:00
8dbf13b1cb
Follow file symlinks in the UI to their target ( #28835 )
...
Symlinks are followed when you click on a link next to an entry, either
until a file has been found or until we know that the link is dead.
When the link cannot be accessed, we fall back to the current behavior
of showing the document containing the target.
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-07-01 06:55:36 +08:00
176962c03e
Add support for 3D/CAD file formats preview ( #34794 )
...
Fix #34775
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-06-30 16:12:25 +08:00
0771a79bf0
Use standalone function to update repository cols ( #34811 )
...
Extract `UpdateRepository`
Follow up #34762
---------
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-06-26 17:23:21 +00:00
75aa23a665
Refactor "change file" API ( #34855 )
...
Follow up the "editor" refactor, use the same approach to simplify code,
and fix some docs & comments
---------
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com >
Co-authored-by: delvh <dev.lh@web.de >
2025-06-25 11:25:20 -07:00
0e629c545a
fix(issue): Replace stopwatch toggle with explicit start/stop actions ( #34818 )
...
This PR fixes a state de-synchronization bug with the issue stopwatch,
it resolves the issue by replacing the ambiguous `/toggle` endpoint
with two explicit endpoints: `/start` and `/stop`.
- The "Start timer" button now exclusively calls the `/start` endpoint.
- The "Stop timer" button now exclusively calls the `/stop` endpoint.
This ensures the user's intent is clearly communicated to the server,
eliminating the state inconsistency and fixing the bug.
---------
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com >
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com >
2025-06-25 07:22:58 +08:00
wxiaoguang and GitHub
6a97ab0af4
Fix team permissions ( #34827 )
...
* Fix #34793
* Fix #33456
2025-06-24 21:24:09 +08:00